Description
This module exploits CVE-2026-46300, a Linux kernel local privilege escalation vulnerability introduced in version 4.10. The flaw resides in the kernel's IPsec ESP-in-TCP handling: when an ESP-encapsulated TCP segment containing a shared fragment (SKBFL_SHARED_FRAG) is received and decrypted, the AES-GCM keystream is applied to page cache pages of the target file without enforcing write permissions. This allows an unprivileged attacker to overwrite arbitrary bytes of a read-only file backed by the page cache. Upstream fix is ported independently by different vendors, so there's release version from which each kernel is not vulnerable anymore.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/local/cve/2026_46300_fragnesiamsf undefined(2026_46300_fragnesia) > show actions ...actions...msf undefined(2026_46300_fragnesia) > set ACTION < action-name >msf undefined(2026_46300_fragnesia) > show options ...show and set options...msf undefined(2026_46300_fragnesia) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub